Re: snort3: Active: active.device is mandatory
Meridoff via Snort-devel <[email protected]> Tue, 15 Oct 2019 16:49:20 +0300
| Newsgroups | gmane.comp.security.ids.snort.devel |
|---|---|
| Message-ID | <CAFfuDwxdOWxmO3u6vi2SOA36xOj1ya3drDBzF7QW6uKhdjz=eQ@mail.gmail.com> |
--===============4422399559300003565== Content-Type: multipart/alternative; boundary="00000000000004925d0594f341d8" --00000000000004925d0594f341d8 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Ok, thanks. But Active.enabled if max_responses > 0 or if react/reject rules used (it calls set_enabled(true)). I have such rule. So , in Active::thread_init() calls open(sc->respond_device.c_str()) for empty device string. I can configure active.device and max_responses. Though I can't find this requirements in doc/active.txt. Thanks =D0=B2=D1=82, 15 =D0=BE=D0=BA=D1=82. 2019 =D0=B3. =D0=B2 15:46, Russ Combs = (rucombs) <[email protected]>: > That error indicates that you have something configured which requires > active support which is not the case for a default config. Apart from > active.max_responses, dce_smb.smb_file_inspection and react, reject, or > rewrite rules will attempt to enable responses. These internal enables > will possibly go away but for now you need to update your config. > > > > *From: *Snort-devel <[email protected]> on behalf of > Meridoff via Snort-devel <[email protected]> > *Reply-To: *Meridoff <[email protected]> > *Date: *Tuesday, October 15, 2019 at 7:12 AM > *To: *"[email protected]" <[email protected]> > *Subject: *Re: [Snort-devel] snort3: Active: active.device is mandatory > > > > Currently if I not cofigured active {}, using defaults for example I have > such thing in log: > > > > " FATAL ERROR: Active response: can't open " > > > > > > =D0=B2=D1=82, 15 =D0=BE=D0=BA=D1=82. 2019 =D0=B3. =D0=B2 14:08, Meridoff = <[email protected]>: > > Hello, if I not configured active.device we have in Active::open (char > *dev) : > > > > * if ( dev && strcasecmp(dev, "ip") )* > > * {* > > * s_link =3D eth_open(dev);* > > *...* > > So here we trying to eth_open for empty device. > > > > May be change for that if no device specifed - we using "ip": > > > > For example: > > * if ( dev && strlen(dev) && strcasecmp(dev, "ip") )* > > * {* > > * s_link =3D eth_open(dev);* > > > > ... > > --00000000000004925d0594f341d8 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div dir=3D"ltr"><div dir=3D"ltr"><div dir=3D"ltr">Ok, tha= nks.=C2=A0</div><div dir=3D"ltr"><div>But Active.enabled if max_responses &= gt; 0 or if react/reject rules used (it calls set_enabled(true)). I have su= ch rule. So ,</div><div>in=C2=A0Active::thread_init() calls open(sc->res= pond_device.c_str()) for empty device string.</div><div><br></div><div>I ca= n configure active.device and max_responses. Though I can't find this r= equirements in doc/active.txt.</div><div><br></div><div>Thanks</div><div><b= r></div></div></div></div></div><br><div class=3D"gmail_quote"><div dir=3D"= ltr" class=3D"gmail_attr">=D0=B2=D1=82, 15 =D0=BE=D0=BA=D1=82. 2019 =D0=B3.= =D0=B2 15:46, Russ Combs (rucombs) <<a href=3D"mailto:[email protected]= ">[email protected]</a>>:<br></div><blockquote class=3D"gmail_quote" sty= le=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);paddi= ng-left:1ex"> <div lang=3D"EN-US"> <div class=3D"gmail-m_1198982280965438284WordSection1"> <p class=3D"MsoNormal">That error indicates that you have something configu= red which requires active support which is not the case for a default confi= g.=C2=A0 Apart from active.max_responses, dce_smb.smb_file_inspection and r= eact, reject, or rewrite rules will attempt to enable responses.=C2=A0 These internal enables will possibly go away bu= t for now you need to update your config.<u></u><u></u></p> <p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p> <div style=3D"border-right:none;border-bottom:none;border-left:none;border-= top:1pt solid rgb(181,196,223);padding:3pt 0in 0in"> <p class=3D"MsoNormal"><b><span style=3D"font-size:12pt;color:black">From: = </span></b><span style=3D"font-size:12pt;color:black">Snort-devel <<a hr= ef=3D"mailto:[email protected]" target=3D"_blank">snort-d= [email protected]</a>> on behalf of Meridoff via Snort-devel = <<a href=3D"mailto:[email protected]" target=3D"_blank">snort-= [email protected]</a>><br> <b>Reply-To: </b>Meridoff <<a href=3D"mailto:[email protected]" target= =3D"_blank">[email protected]</a>><br> <b>Date: </b>Tuesday, October 15, 2019 at 7:12 AM<br> <b>To: </b>"<a href=3D"mailto:[email protected]" target=3D"_= blank">[email protected]</a>" <<a href=3D"mailto:snort-de= [email protected]" target=3D"_blank">[email protected]</a>><= br> <b>Subject: </b>Re: [Snort-devel] snort3: Active: active.device is mandator= y<u></u><u></u></span></p> </div> <div> <p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p> </div> <div> <div> <div> <p class=3D"MsoNormal">Currently if I not cofigured active {}, using defaul= ts for example I have such thing in log:<u></u><u></u></p> </div> <div> <p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p> </div> <div> <p class=3D"MsoNormal">" FATAL ERROR: Active response: can't open = "=C2=A0<u></u><u></u></p> </div> <div> <p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p> </div> </div> </div> <p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p> <div> <div> <p class=3D"MsoNormal">=D0=B2=D1=82, 15 =D0=BE=D0=BA=D1=82. 2019 =D0=B3. = =D0=B2 14:08, Meridoff <<a href=3D"mailto:[email protected]" target=3D"_= blank">[email protected]</a>>:<u></u><u></u></p> </div> <blockquote style=3D"border-top:none;border-right:none;border-bottom:none;b= order-left:1pt solid rgb(204,204,204);padding:0in 0in 0in 6pt;margin-left:4= .8pt;margin-right:0in"> <div> <div> <div> <p class=3D"MsoNormal">Hello, if I not configured active.device we have in = Active::open (char *dev) : <u></u><u></u></p> <div> <p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p> </div> <div> <div> <p class=3D"MsoNormal"><i>=C2=A0 =C2=A0 if ( dev && strcasecmp(dev,= "ip") )</i><u></u><u></u></p> </div> <div> <p class=3D"MsoNormal"><i>=C2=A0 =C2=A0 {</i><u></u><u></u></p> </div> <div> <p class=3D"MsoNormal"><i>=C2=A0 =C2=A0 =C2=A0 =C2=A0 s_link =3D eth_open(d= ev);</i><u></u><u></u></p> </div> </div> <div> <p class=3D"MsoNormal"><i>...</i><u></u><u></u></p> </div> <div> <p class=3D"MsoNormal">So here we trying to eth_open for empty device.<u></= u><u></u></p> </div> <div> <p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p> </div> <div> <p class=3D"MsoNormal">May be change for that if no device specifed - we us= ing "ip":<u></u><u></u></p> </div> <div> <p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p> </div> <div> <div> <p class=3D"MsoNormal">For example:<u></u><u></u></p> </div> <div> <div> <p class=3D"MsoNormal"><i>=C2=A0 =C2=A0 if ( dev && strlen(dev) =C2= =A0&& strcasecmp(dev, "ip") )</i><u></u><u></u></p> </div> <div> <p class=3D"MsoNormal"><i>=C2=A0 =C2=A0 {</i><u></u><u></u></p> </div> <div> <p class=3D"MsoNormal"><i>=C2=A0 =C2=A0 =C2=A0 =C2=A0 s_link =3D eth_open(d= ev);</i><u></u><u></u></p> </div> </div> <div> <p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p> </div> <div> <p class=3D"MsoNormal">...<u></u><u></u></p> </div> </div> </div> </div> </div> </blockquote> </div> </div> </div> </blockquote></div> --00000000000004925d0594f341d8-- --===============4422399559300003565== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Snort-devel mailing list [email protected] https://lists.snort.org/mailman/listinfo/snort-devel Please visit http://blog.snort.org for the latest news about Snort! --===============4422399559300003565==--